CVE-2025-13294EPSS p33.0%
CVE-2025-13294CVE-2025-13294
Description
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.
Scoring
| EPSS | 0.40% probability of exploitation · percentile 33.0% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |